For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/compliance/iso-27001-or-nis2-first.md.
Compliance ↗

ISO 27001 or NIS2 first?

Build shared security processes, but track legal duties and certification separately. Applicable legal deadlines take priority over commercial preferences.

AI-generated illustration: Workshop comparing obligations with a security management system.

The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.

Start with the obligations that apply to the business today. A legal duty cannot be deferred because a customer would prefer an ISO 27001 certificate first.

After that, look for shared work. Risk assessment, incident handling, supplier oversight and access management can support both an ISO 27001 management system and NIS2 preparation. There is little value in maintaining separate versions of the same records.

Separate the outcomes

ISO 27001 certification is an independent assessment of a defined management system. NIS2 creates legal obligations through the applicable national implementation. An ISO certificate does not establish NIS2 compliance.

NIS2’s requirements include risk management, reporting and management responsibilities. Scope, registration, supervision and sector-specific rules also need attention. The difference cannot be reduced to adding a reporting template and a board meeting.

Identify the applicable jurisdictions

Norway’s current Digital Security Act implements NIS1. Norwegian NIS2 implementation is a separate process. Assess current Norwegian duties while tracking the forthcoming framework.

A Norwegian business may also need to assess an EU establishment or covered cross-border digital service under the relevant country’s rules. Customer contracts can introduce security requirements without making the supplier directly subject to every NIS2 duty.

Put the work in one plan

List each binding obligation, its deadline and its owner. Then map the existing controls and records to those requirements and the chosen ISO scope.

Fix urgent security gaps and current legal shortfalls first. Schedule certification preparation around confirmed customer requirements and the certification body’s calendar. Avoid promising that one assessment will automatically satisfy another.

For example, an incident process can serve several regimes while containing separate triggers, recipients and deadlines for each. An access review can provide one authoritative record referenced by several assessments.

The ISO 27001 checklist and NIS2 preparation guide cover the respective work. The goal is shared operation with a clear account of what each obligation still requires.

← Back to all insights
Questions or inquiry? [email protected] Contact us →